It starts with a client and a late-night idea on a napkin. It turns into a SOC2-certified product trusted by Police, Government Agencies and the TSA.
You'll hear how we partnered with an ambitious state to augment their physical Driver's License with a new Digital ID built from the ground up. One that lets you access public services, legally buy age-restricted items and even board planes with just your phone.
Why does this matter? Unlike typical apps, failing here means anyone can forge an identity. With no mature framework to follow, we synchronised compliance, DevSecOps, and user-privacy across four orgs, three audit firms, and one very impatient legislature.
Key stories we'll unpack:
- What's going on with your data, and how an identity app works.
- Building a security-as-code pipeline that ships and keeps auditors happy.
- Breaking liveness detection and facial recognition implementations.
- When the ground shifts and new interoperability standards cause fraudulent verifications.
- How-to on achieving SOC2 certifications, encompassing everything from the mobile app to manufacturing plants.
- How to prove security to clients: threat modeling, pen tests, and 3rd party assurance.
- Integrating blockchain and self-sovereign identity.
- Successfully launching the final product with TSA approval for boarding flights.
If you've ever wondered how to 'secure it' when there are no roadmaps, no precedents, and the stakes are literally sky-high, this talk is for you. This session isn't just a story—it's a playbook for navigating the unknown, where security isn't just a requirement; it's the product.
View on BlackHat Sector Schedule